CVE-2026-101018 | dayrui XunruiCMS up to 4.7.2 Group Editing Home.php group_all_edit groupid sql injection

SecurityVulns

A vulnerability, which was classified as problematic, has been found in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection.

This vulnerability is tracked as CVE-2026-101018. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More